diff --git a/hosts/fw.cloonar.com/modules/firewall.nix b/hosts/fw.cloonar.com/modules/firewall.nix index 964f69b..2b69c5d 100644 --- a/hosts/fw.cloonar.com/modules/firewall.nix +++ b/hosts/fw.cloonar.com/modules/firewall.nix @@ -10,17 +10,21 @@ iptables -A INPUT -i wg_cloonar -j ACCEPT iptables -A INPUT -p udp -i smart -m multiport --dports 53,67,68 -j ACCEPT iptables -A INPUT -p udp -i multimedia -m multiport --dports 53,67,68 -j ACCEPT + iptables -A INPUT -p udp -i podman0 -m multiport --dports 53,67,68 -j ACCEPT iptables -A INPUT -p tcp -i smart -m multiport --dports 80,443,453 -j ACCEPT iptables -A INPUT -p tcp -i multimedia -m multiport --dports 80,443,453 -j ACCEPT + iptables -A INPUT -p tcp -i podman0 -m multiport --dports 80,443,453 -j ACCEPT iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT iptables -A FORWARD -i wan -d 10.42.0.0/16 -j ACCEPT iptables -A FORWARD -i lan -d 10.42.0.0/16 -j ACCEPT + iptables -A FORWARD -i podman0 -d 10.42.0.0/16 -j ACCEPT iptables -A FORWARD -i wg_cloonar -d 10.42.0.0/16 -j ACCEPT iptables -A FORWARD -i lan -o wan -j ACCEPT iptables -A FORWARD -i server -o wan -j ACCEPT + iptables -A FORWARD -i podman0 -o wan -j ACCEPT iptables -A FORWARD -i server-shim -o wan -j ACCEPT iptables -A FORWARD -i multimedia -o wan -j ACCEPT iptables -A FORWARD -i smart -o wan -j ACCEPT